目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2017-0089 PoC — Microsoft Windows Uniscribe 缓冲区错误漏洞

来源
关联漏洞
标题: Microsoft Windows Uniscribe 缓冲区错误漏洞 (CVE-2017-0089)
Description:Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。Uniscribe(又名Unicode Script Processor)是其中的一个能够使Windows操作系统正确演示Unicode文字的组件。 Microsoft Windows中的Uniscribe存在远程代码执行漏洞。远程攻击者可借助特制的Web站点利用该漏洞执行任意代码。以下版本受到影响:Microsoft Windows Vista SP2,Windows Server 2008 SP2和R2 SP1
Description
CVE-2017-0089 Learn more at National Vulnerability Database (NVD) • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
介绍
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0089
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, and CVE-2017-0090.
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
BID:96606
URL:http://www.securityfocus.com/bid/96606
CONFIRM:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0089
EXPLOIT-DB:41652
URL:https://www.exploit-db.com/exploits/41652/
SECTRACK:1037992
URL:http://www.securitytracker.com/id/1037992
Microsoft Corporation
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →